12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

318 IDS eventsIntrusion attemptsHTTP MDAC Component QueryBase Event:Details:Response:HTTP_MDAC_COMPONENT_QUERYMicrosoft Data Access Components (MDAC) contains a buffer overflow vulnerability in a RemoteData Services (RDS) component. The server side RDS component affected is called the RDS DataStub, while the client side is called the Data Space control.Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code, or atthe very least, cause a denial-of-service.Microsoft has released patches that eliminate the vulnerability. They also rectify the vulnerabilitydescribed in: MS00-086).This patch does not address the new variants discovered by Georgi Guninski on November 27,2000.After resolving the issue, it is recommended that you:■■■■■■■■Block external access to Web services at the network boundary, unless service isrequired by external parties.Run all client software as a non-privileged user with minimal access rights.Do not run Internet Explorer as a user with greater privileges than required.Run all server processes as non-privileged users with minimal access rights.Running IIS as an unprivileged user will limit the consequences of successfulexploitation.Do not accept communications that originate from unknown or untrusted sources.Do not visit unknown or untrusted Web sites from critical systems.Do not open HTML email from unknown or untrusted users.Affected: Microsoft Data Access Components (MDAC) 2.1Microsoft Data Access Components (MDAC) 2.5Microsoft Data Access Components (MDAC) 2.6Microsoft Internet Explorer 5.01Microsoft Internet Explorer 5.5Microsoft Internet Explorer 6.0False Positives: None known.<strong>Reference</strong>s: <strong>Security</strong> Focus BID: 6214CAN-2002-1142Microsoft <strong>Security</strong> Bulletin MS02-065CERT Advisory CA-2002-33 Heap Overflow Vulnerability in Microsoft Data Access Components(MDAC)

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!